311
Step Command
Remarks
policy template.
6.
Specify an IKE profile for the
IPsec policy.
ike-profile
profile-name
By default, no IKE profile is
specified for the IPsec policy
template.
You can specify only one IKE
profile for an IPsec policy template
and the IKE profile cannot be
used by another IPsec policy
template or IPsec policy.
For more information about IKE
profiles, see "
."
7.
Specify an IKEv2 profile for
the IPsec policy template.
ikev2-profile
profile-name
By default, no IKEv2 profile is
specified for the IPsec policy
template.
You can specify only one IKEv2
profile for an IPsec policy
template.
For more information about IKEv2
profiles, see "
8.
(Optional.) Specify the local
IP address of the IPsec
tunnel.
local-address
{
ipv4-address
|
ipv6
i
pv6-address
}
By default, the local IPv4 address
of IPsec tunnel is the primary IPv4
address of the interface to which
the IPsec policy is applied, and
the local IPv6 address of the
IPsec tunnel is the first IPv6
address of the interface to which
the IPsec policy is applied.
The local IP address specified by
this command must be the same
as the IP address used as the
local IKE identity.
9.
(Optional.) Specify the
remote IP address of the
IPsec tunnel.
remote-address
{ [
ipv6
]
host-name
|
ipv4-address
|
ipv6
ipv6-address
}
By default, the remote IP address
of the IPsec tunnel is not
specified.
10.
(Optional.) Configure the
IPsec SA lifetime.
sa
duration
{
time-based
seconds
|
traffic-based
kilobytes
}
By default, the global SA lifetime
settings are used.
11.
(Optional.) Set the IPsec SA
idle timeout.
sa idle-time seconds
By default, the global SA idle
timeout is used.
12.
(Optional.) Enable the Traffic
Flow Confidentiality (TFC)
padding feature.
tfc enable
By default, the TFC padding
feature is disabled.
13.
Return to system view.
quit
N/A
14.
Configure the global SA
lifetime.
ipsec
sa
global-duration
{
time-based
seconds
|
traffic-based
kilobytes
}
By default, time-based SA lifetime
is 3600 seconds, and
traffic-based SA lifetime is
1843200 kilobytes.
15.
(Optional.) Enable the global
IPsec SA idle timeout
feature, and set the global
SA idle timeout.
ipsec sa idle-time seconds
By default, the global IPsec SA
idle timeout feature is disabled.
16.
Create an IPsec policy by
using the IPsec policy
template.
ipsec
{
ipv6-policy
|
policy
}
policy-name seq-number
isakmp
template
template-name
By default, no IPsec policies exist.
Summary of Contents for FlexFabric 5940 SERIES
Page 251: ...238 ...